The four-file project has no tests, security scanning, or security policy, and its README offers little integration guidance. It is MIT-licensed, stable, and has no install-time scripts, which reduces adoption friction but does not offset the maintenance risk.
42%
Total Score
0
71
83
The latest release was in December 2022, with no releases in the following three years and nine months. Five releases arrived early in the package's life, but the prolonged gap materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided activity signal compensates for this lack of recent maintenance.
The package includes a README and release notes for this version, but it has no tests and no changelog. Missing tests are normal in a published artifact, while the short README provides only installation guidance for a library consumers must integrate.
Composer is used for the build, but the repository reports no security scanning tools. That is a maintenance and transparency gap for a package handling uploaded files.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, although it is secondary to the stronger evidence of inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.